Sample viewer

vx.netlux.org/Virus.DOS.TPE.Duwende.1904

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:56:23.155452786Z 255 PC: 12b06 | UNKNOWN!
2018-12-17T21:56:23.157433471Z 74 PC: 12b21 | Reallocate memory
2018-12-17T21:56:23.159105174Z 72 PC: 12b29 | Allocate memory
2018-12-17T21:56:23.160831083Z 44 PC: 9fb3f | Get time 0x9fb3f: in al, 0x40
0x9fb41: mov ah, al
0x9fb43: in al, 0x40
0x9fb45: xor ax, cx
0x9fb47: xor dx, ax
0x9fb49: jmp 0x9fb70
0x9fb4b: call 0x9fb53
0x9fb4e: or ax, ax
0x9fb50: je 0x9fb4b
0x9fb52: ret
0x9fb53: push dx
0x9fb54: push cx
0x9fb55: push bx
0x9fb56: in al, 0x40
0x9fb58: add ax, 0x5c09
0x9fb5b: mov dx, 0xff8b
0x9fb5e: mov cx, 7
0x9fb61: shl ax, 1
0x9fb63: rcl dx, 1
0x9fb65: mov bl, al
2018-12-17T21:56:23.164664291Z 53 PC: 9f4a9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:56:23.166076626Z 37 PC: 9f4b8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:56:23.167468572Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T21:56:23.181584501Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')